Skip to main content

The Office 365 Module

Syncs license and user data from Microsoft 365 tenants, showing license assignments and MFA registration status.

The Office 365 Module syncs license and user data from your clients' Microsoft 365 tenants, giving both your team and your clients visibility into license assignments, license types, MFA status, and sign-in activity.

What syncs from Office 365

Once a client's Microsoft 365 tenant is connected, Strategy Overview pulls in:

  • User accounts with their assigned licenses

  • License types and counts

  • MFA status for each user

  • Last Signed In date for each user, useful for spotting stale accounts and unused licenses. This column requires Microsoft Entra ID P1 or higher on the client's tenant.

This data updates automatically through sync, so you're always working with current information.

Understanding MFA status

Strategy Overview shows MFA as "enabled" only when the user has actually completed MFA registration. This can differ from what the Office 365 admin portal shows, and it's not a bug - it's a difference in how Microsoft exposes MFA data to third-party applications.

The Office 365 admin portal can show statuses like "Enabled" (MFA assigned but not yet set up) and "Enforced" (MFA setup required and completed). Strategy Overview can only detect whether the user has actually registered MFA, not whether it's been assigned to them. So if an admin has enabled MFA for a user but that user hasn't finished the registration process, Office 365 may show "Enabled" while Strategy Overview shows "Disabled."

Here's how common scenarios look across both systems:

Scenario

Office 365 MFA Status

Strategy Overview MFA Status

MFA assigned, user hasn't registered

Enabled

Disabled

MFA enforced, user hasn't completed setup

Enforced

Disabled

User completed MFA registration

Enabled or Enforced

Enabled

Contact (not a real user account)

N/A

N/A

Deleted user

Varies

Disabled

Guest user, MFA not registered

Enabled or N/A

Disabled

If you see a discrepancy between the two systems, the most common cause is that the user still needs to complete their MFA registration. You can use Strategy Overview's MFA column to quickly identify which users haven't finished setup.

Per-tenant setup

Unlike your PSA (which connects once and syncs all companies), Office 365 requires a separate connection for each client's Microsoft 365 tenant. The tenant connection process is covered in the Integrations collection.

Customizing columns

Like other Parts in Strategy Overview, the Office 365 Module supports column customization. You can show or hide columns, reorder them, and rename labels to match what makes sense for your team and clients. Column changes are managed at the template level.

Beyond the basics, the module carries columns covering security posture, account lifecycle, organizational detail, and mailbox data. Some are on by default and the rest are there to turn on when you want them. None of them require new Microsoft consent: the permissions granted when you connected the tenant already cover all of them.

Columns also support a select filter, so you can narrow the user list to specific values, for example only guest accounts or only users who haven't registered MFA.

Note: A few columns depend on the client's Microsoft licensing rather than on your setup. Last Signed In needs Microsoft Entra ID P1 on the client's tenant, which Business Premium includes and Business Basic and Standard do not. Where the licensing isn't there, the column is empty rather than showing an error, so an empty column here is not a sync problem.

Merging Office 365 with Contacts

You can merge Office 365 data with your Contacts data to get a unified view that combines PSA contact information with Microsoft 365 license and MFA details. This is useful for identifying which contacts have licenses assigned, verifying MFA compliance, and cleaning up licensing.

Merging is enabled at the template level. You can choose to build from Contacts and add Office 365 data, or build from Office 365 and add Contact data. The connection is made through the user email field. After enabling the merge, create a new Report version to see the combined data.

Using Office 365 data with clients

The Office 365 Module is one of the most practical things you can share with clients through the portal. Clients can self-audit their license usage, verify that the right people have the right licenses, and confirm MFA is enabled across their organization. This reduces billing questions and gives clients more ownership of their Microsoft 365 environment.

Did this answer your question?